System Overview
Complete system architecture and core concepts
What is This System?
An enterprise-grade RBAC (Role-Based Access Control) and scheduling system for managing incident response teams within a hierarchical installation topology. Allows administrators to:
• Create and manage incident response teams with ordered member rosters
• Assign teams to nodes in an organizational hierarchy
• Plan timezone-aware team coverage in week-based planner/form modes with staged edits and recurrence exceptions
• Validate permissions in real-time using role-based scopes and direct-node routing
• Enforce RBAC guardrails to prevent unauthorized assignmentsKey Components
• **Users**: Directory of team members with optional global admin flag • **UserScopes**: Define read boundaries and RBAC permissions per user • **IncidentTeams**: Containers for nullable escalation policies and ordered team rosters • **InstallationNodes**: 4-tier hierarchy (Account → SubAccount → Zone → Installation) • **Escalation Policy**: Optional acknowledgement timeout and bounded roster-loop configuration • **Members**: Ordered, equal team members with visible positions 1..N and persisted escalationOrder 0..N-1 • **MemberEscalationRoster**: Shared roster editor used in provisioning and Manage Teams, built on @iampoul/react-order with dnd-kit peer dependencies for pointer/touch/keyboard reordering • **CoverageSchedules**: Mock timezone-aware recurring team coverage stored in memory • **OccurrenceExceptions**: Cancelled or replacement occurrences keyed by original start • **SchedulePlanner**: Week-based planner with draggable team chips and staged batch saves
4 Main Workflows
1. **Create Team** - Provision teams with ordered members and assign scopes 2. **Assign Teams** - Map teams to hierarchy nodes with permission validation 3. **Manage Teams** - View and edit teams with the shared ordered roster 4. **Plan Coverage** - Use Planner/Form modes to stage week-based coverage changes